CVE-2026-103110: Pexip Infinity Conferencing Node Remote Code Execution
A critical remote code execution vulnerability tracked as CVE-2026-103110 has been disclosed in Pexip Infinity, a widely deployed enterprise and government video conferencing platform. The flaw carries a CVSS v3.1 score of 9.8 (Critical) and stems from improper input validation that lets a remote, unauthenticated attacker execute arbitrary code as an unprivileged user on a Pexip Infinity Conferencing Node — the component that terminates and mixes live call media.
The vulnerability was published September 30, 2026, via the National Vulnerability Database (NVD), with Pexip publishing corresponding guidance on its official security bulletins page. As of publication there is no public proof-of-concept exploit and the flaw is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, but the combination of network exploitability, no authentication requirement, and no user interaction makes rapid weaponization plausible.
Vulnerability Overview
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-103110 |
| CVSS v3.1 Score | 9.8 (Critical) |
| CVSS Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Weakness Class | Improper Input Validation (several trackers also cite CWE-787, Out-of-Bounds Write) |
| Affected Component | Pexip Infinity Conferencing Node |
| Attack Vector | Network |
| Authentication Required | None |
| User Interaction Required | None |
| Primary Impact | Remote Code Execution (unprivileged user context) |
| Public Exploit / PoC | None known at disclosure |
| CISA KEV Listed | No |
| Source | NVD / Pexip Security Bulletins |
Technical Details
Root Cause
Pexip Infinity Conferencing Nodes process a large volume of attacker-reachable, network-facing input as part of real-time call signaling and media handling. NVD's published description frames the defect as improper input validation reachable by a remote party without any prior authentication; several third-party vulnerability trackers additionally classify the underlying weakness as CWE-787 (Out-of-Bounds Write), which would be consistent with memory corruption triggered by malformed input reaching an unchecked buffer or parsing routine. Pexip has not published full internal technical detail on the exact vector, which is standard practice for an unpatched or newly patched critical flaw to limit exploitation windows.
Because Conferencing Nodes are the media-plane workhorses of a Pexip Infinity deployment — they are explicitly designed to accept inbound call signaling and media from external endpoints — this is a pre-authentication, network-reachable attack surface by design, which is what drives the severity rating.
Exploitation Path
Attacker (network-reachable, no credentials)
→ Crafted call-signaling / media input sent to Pexip Conferencing Node
→ Malformed data processed without sufficient validation
→ Out-of-bounds condition / unsafe input handling triggered
→ Arbitrary code execution as an unprivileged user on the node
→ Potential pivot toward Management Node or internal network segments
CVSS Breakdown
The 9.8 score reflects:
- Attack Vector: Network — exploitable without local or adjacent-network access
- Attack Complexity: Low — no special conditions or race windows required
- Privileges Required: None — pre-authentication exploitation
- User Interaction: None — fully automatable
- Confidentiality / Integrity / Availability Impact: High across all three axes
Code execution occurs as an unprivileged user rather than root, which somewhat limits (but does not eliminate) the blast radius of an initial compromise — privilege escalation and lateral movement would typically be required for full node takeover.
Impact Assessment
| Impact Area | Description |
|---|---|
| Code Execution | Arbitrary code execution on the Conferencing Node, initially as an unprivileged user |
| Confidentiality | Exposure of in-progress call media, signaling metadata, and node configuration |
| Integrity | Potential tampering with conference sessions or node behavior |
| Availability | Node crash or disruption of active and future conferences hosted on the affected node |
| Lateral Movement | A compromised Conferencing Node could serve as a foothold toward the Management Node or internal network |
| Sector Exposure | Pexip Infinity is widely used by government, healthcare, legal, and enterprise organizations for secure video conferencing — a compromise could expose sensitive, regulated communications |
Affected Systems
| Product / Version | Status |
|---|---|
| Pexip Infinity before 38.2 (38.1 and earlier) | Affected |
| Pexip Infinity 39.0 | Affected |
| Pexip Infinity 39.1 | Affected |
| Pexip Infinity 40.0 | Affected |
| Pexip Infinity 38.2 and later 38.x builds | Not affected (fixed) |
Aggregated vulnerability-tracker data indicates Pexip has shipped fixed builds across every affected branch — reported as 38.2, 39.2, 40.1, and 41.0. Administrators should treat these as a starting point only and confirm the exact fixed build number for their deployed branch against Pexip's official bulletin before scheduling an upgrade.
Remediation
For Pexip Administrators
- Identify your deployed version — check the Management Node version against the affected list above (before 38.2, or 39.0/39.1/40.0).
- Upgrade immediately to the fixed build for your branch, prioritizing internet-facing or externally reachable Conferencing Nodes.
- Consult the official bulletin at
docs.pexip.com/admin/security_bulletins.htmfor the authoritative fixed-version matrix and any version-specific upgrade notes. - Contact Pexip Support if an immediate upgrade is not feasible — Pexip's bulletin indicates mitigation options can be discussed directly with support for organizations that cannot patch right away.
For Security Teams
- Inventory all Pexip Infinity nodes (Management Node and every Conferencing Node) and confirm patch status fleet-wide — do not assume uniform versions across nodes.
- Restrict external exposure of Conferencing Nodes where possible, limiting inbound signaling/media traffic to expected endpoints and known IP ranges while patching is in progress.
- Monitor for anomalous behavior on Conferencing Nodes — unexpected process spawns, crashes, or resource spikes correlated with inbound call signaling.
- Review logs retroactively for malformed or unusual signaling/media traffic predating the patch, since no PoC being public today does not rule out quiet pre-disclosure probing.
- Segment the Pexip deployment from sensitive internal networks so a compromised Conferencing Node cannot directly reach high-value systems.
Defense-in-Depth
Priority 1: Patch to the fixed build for your branch (38.2 / 39.2 / 40.1 / 41.0 — confirm with Pexip)
Priority 2: Restrict/firewall external access to Conferencing Nodes to only what is operationally required
Priority 3: Network-segment Conferencing Nodes away from sensitive internal assets
Priority 4: Enable enhanced logging/monitoring on nodes during the patch window
Priority 5: Engage Pexip Support for interim mitigation if patching must be delayed
Key Takeaways
- CVE-2026-103110 is a CVSS 9.8 critical, pre-authentication remote code execution vulnerability in Pexip Infinity Conferencing Nodes.
- The flaw requires no authentication and no user interaction, and is remotely exploitable over the network — a textbook critical-severity profile.
- Affected versions: Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0; fixed builds are reported for every branch (38.2, 39.2, 40.1, 41.0) — verify exact numbers with Pexip.
- Code executes as an unprivileged user initially, meaning privilege escalation or lateral movement would typically follow a successful initial compromise.
- No public proof-of-concept and no CISA KEV listing exist as of disclosure, but organizations should not treat this as low urgency given the attack profile.
- Patch immediately, prioritizing internet-facing Conferencing Nodes, and contact Pexip Support for interim mitigation if an upgrade cannot happen right away.